Managing your M365 Tenant Flashcards
(55 cards)
Roles.
collections of permissions that allow users and groups to perform specific tasks or functions within Microsoft 365
Scopes.
Scopes are filters that limit the range or extent of a role. You can apply scopes to roles to restrict the access and management of resources within Microsoft 365.
Assignments.
the links that connect roles and scopes to users and groups. Assignments are the final step in the permission model, as they determine who can do what and where within Microsoft 365
Conditional access policies
access policies based on factors like user location, device type, and risk profile.
Risk-based authentication.
Microsoft Entra ID evaluates user behavior and context to determine risk levels. Security teams can implement extra authentication steps when suspicious activity is detected
Passwordless authentication
reduces reliance on traditional passwords
Role Management role
allows users to view, create, and modify role groups in the Microsoft Defender portal.
Billing administrator
- Manage all aspects of billing.
- Create and manage support tickets in the Microsoft Entra admin center
Compliance administrator
- Stay compliant with any regulatory requirements.
- Manage eDiscovery cases.
- Maintain data governance policies across Microsoft 365 locations, identities, and apps.
- Monitor compliance-related policies across Microsoft 365 services.
- Manage compliance alerts.
- Perform legal and data investigations.
- Manage Data Subject Requests.
- View all Intune audit data.
Exchange administrator
- Recover deleted items in a user’s mailbox.
- Determine how long to retain deleted email before the system permanently deletes it.
- Set up mailbox features such as the mailbox sharing policy, which determines how users can share calendar and contacts information with others outside of your organization.
- Set up, Send As, and Send on Behalf delegates for someone’s mailbox; for example, when an executive wants their assistant to have permission to send mail on the executive’s behalf.
- Create shared mailboxes so a group of people can monitor and send email from a common email address.
- Set up anti-spam and malware filters for the organization.
- Manage Microsoft 365 Groups.
Global reader
the read-only counterpart to Global Administrator. Assign Global Reader instead of Global Administrator for planning, audits, or investigations.
Groups administrator
- Create, edit, delete, and restore Microsoft 365 groups.
- Create and update group creation, expiration, and naming policies.
- Create, edit, and delete Microsoft Entra security groups.
Helpdesk administrator
- Reset passwords.
- Force users to sign out.
- Manage service requests.
- Monitor service health.
License administrator
- Reprocess license assignments for group-based licensing.
- Assign product licenses to groups for group-based licensing.
Message center reader
monitor notifications and advisory health updates in the Message center for their organization on configured services such as Exchange, Intune, and Microsoft Teams.
Office Apps administrator
- Use the Office cloud policy service to create and manage cloud-based policies for Office.
- Create and manage service requests.
- Manage the What’s New content that users see in their Office apps.
- Monitor service health.
Password administrator
reset passwords for nonadministrators and Password Administrators. Users with this role have limited ability to manage passwords.
Power Platform administrator
- Manage all admin features for Power Apps, Flows, and Data loss prevention policies.
- Create and manage service requests.
- Monitor service health.
Reports reader
- View usage data and the activity reports in the Microsoft 365 admin center.
- Get access to the Power BI adoption content pack.
- Get access to sign-in reports and activity in Microsoft Entra ID.
- View data returned by Microsoft Graph reporting API.
Security administrator
- Manage security threats and alerts.
- View reports.
- Monitor and respond to suspicious security activity.
- Assign roles.
- Manage machine groups.
- Configure endpoint threat detection and automated remediation.
- View, investigate, and respond to alerts.
- View machines/device inventory.
- View user, device, enrollment, configuration, and application information in Intune.
- Define the threshold and duration for lockouts when failed sign-in events happen.
- Configure custom banned password list or on-premises password protection.
Service Support administrator
- Open and manage service requests.
- View and share message center posts.
- Monitor service health.
SharePoint administrator
- Create and delete sites.
- Manage site collections and global SharePoint settings.
- Define the user profile policies and settings for the organization, including management of promoted sites.
- Create Business Connectivity Services (BCS) connections to data sources that are outside the SharePoint Online site.
- Manage records in place, which means that you can leave a document in its current location on a site, or store records in a specific archive.
- Customize the search experience for users.
- Configure SharePoint Online hybrid with an on-premises SharePoint Online site.
- Use InfoPath Forms Services in SharePoint Online to deploy the organization’s forms to its sites, enabling users to fill out these forms in a web browser.
Teams administrator
- Manage and create Microsoft 365 groups.
- Manage meetings.
- Manage conference bridges.
- Manage all org-wide settings, including federation, teams upgrade, and teams client settings.
- Troubleshoot communication issues within Teams.
User administrator
- Add users and groups.
- Assign licenses.
- Manage most users properties.
- Create and manage user views.
- Update password expiration policies.
- Manage service requests.
- Monitor service health.
The user admin can also complete the following actions:
- Manage usernames.
- Delete and restore users.
- Reset passwords.
- Force users to sign out.
- Update (FIDO) device keys.